•  
      request #9410 Tuleap Realtime server should enable HTTP Strict Transport Security header
    Infos
    #9410
    Thomas Gerbet (tgerbet)
    2018-03-07 09:43
    2016-08-20 00:19
    9687
    Details
    Tuleap Realtime server should enable HTTP Strict Transport Security header
    The Tuleap Realtime server can already be used through HTTPS, we should enforce that by enabling HSTS. This will help protecting the communication between the server and the clients against downgrade attack.

    Specification: https://tools.ietf.org/html/rfc6797
    OWASP description and explanation: https://www.owasp.org/index.php/HTTP_Strict_Transport_Security_Cheat_Sheet
    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    Closed
    2018-03-07
    Attachments
    Empty
    References
    Referenced by request #9410

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2018-03-07 09:43
    Declining it for now.
    There is some technical limitations with the library we use and setting the HSTS header can have subsequent impacts if the domain is reused for something else so it should be an option.

    • Status changed from Under review to Closed
    • Close date set to 2018-03-07